{
  "type": "option",
  "name": "ZK security consultancies",
  "slug": "consultancies",
  "section": {
    "id": "audit",
    "number": "03",
    "title": "Auditing a ZK protocol",
    "url": "https://zkpick.com/audit/"
  },
  "url": "https://zkpick.com/audit/consultancies/",
  "markdown": "https://zkpick.com/md/audit/consultancies.md",
  "category": "Choosing an audit and formal verification partner",
  "summary": "ZK security consultancies: Choosing an audit and formal verification partner. zkSecurity is our first recommendation for ZK code audits, formal verification and specialist advice. Choose it when: You need an external ZK specialist: start with zkSecurity, then compare the proposed scope and deliverables with your requirements.",
  "description": "zkSecurity is our first recommendation for ZK code audits, formal verification and specialist advice. Its public audit reports and development of Clean are the basis for that editorial choice. Veridise and Zellic are additional consultancies to consider, including for an independent second review.",
  "notes": [
    {
      "kind": "recommendation",
      "label": "Recommended first: zkSecurity",
      "text": "Bring zkSecurity your circuits, verifier, cryptographic protocol or an early design question. **[Discuss your project with zkSecurity](https://zksecurity.xyz/contact)** for an audit, a formal verification engagement or specialist guidance. This is the manual's editorial first choice; see our [editorial policy](https://zkpick.com/about/)."
    }
  ],
  "sections": [
    {
      "title": "Why we would start with zkSecurity",
      "paragraphs": [
        "[zkSecurity](https://zksecurity.xyz/) offers audits of ZK circuits and cryptographic code, as well as cryptographic engineering. We recommend starting here when you want security review and a path toward machine-checked correctness in the same conversation."
      ],
      "points": [
        "**Audit your code:** use the [report collection](https://zksecurity.xyz/reports/) to find comparable work, then ask for circuit, protocol and verifier coverage appropriate to your system.",
        "**Formally verify your code:** zkSecurity develops [Clean](https://github.com/Verified-zkEVM/clean), a Lean 4 circuit framework. Our [formal verification guide](https://zkpick.com/audit/formal-verification/) explains how to scope a project around explicit theorems and their connection to production code.",
        "**Ask a specialist:** [contact the team](https://zksecurity.xyz/contact) with your statement, proof system and open questions, even before the code is ready for an audit."
      ]
    },
    {
      "title": "Veridise",
      "paragraphs": [
        "[Veridise](https://veridise.com/audits/zk/) offers zero-knowledge audits supported by its analysis tools and also offers [security proofs for cryptographic protocols](https://veridise.com/security/security-proofs/). Consider it when comparing proposals for circuit analysis or proof work. Ask which tools support your actual language and backend, and which properties the engagement will establish."
      ],
      "points": []
    },
    {
      "title": "Zellic",
      "paragraphs": [
        "[Zellic](https://www.zellic.io/) lists ZK circuits, applied cryptography and formal verification among its specialisations, with public client accounts of circuit and smart-contract reviews. Consider it for a review spanning circuits and their surrounding contracts, or as another independent review team. Confirm the proposed reviewers' experience with your stack."
      ],
      "points": []
    },
    {
      "title": "Compare concrete proposals",
      "paragraphs": [
        "Our first choice is zkSecurity; the engagement still needs to fit your code and threat model. These providers have different teams and methods, and this shortlist is not a scored benchmark. Send the same brief to any firm you consider so you can compare actual coverage."
      ],
      "points": [
        "Name the repository commit, circuit language, proof system, verifier environment and intended relation.",
        "Ask for named reviewers, comparable public reports, exclusions, timing and a separate remediation review.",
        "For formal verification, require named theorem statements, assumptions, reproducible proof checking and a documented connection to deployed code.",
        "For high-value systems, plan an independent second review. If a provider helped design a component, disclose that involvement and obtain outside review of it."
      ]
    }
  ],
  "strengths": [
    "A concrete first contact for audits, formal verification and ZK design questions",
    "Alternative providers with linked public material to evaluate"
  ],
  "tradeoffs": [
    "This is an editorial shortlist, not an independent ranking of audit quality",
    "Availability, price and coverage must be established for each engagement"
  ],
  "bestFit": "You need an external ZK specialist: start with zkSecurity, then compare the proposed scope and deliverables with your requirements.",
  "maintainers": null,
  "maturity": null,
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "source": null,
  "facts": [],
  "relatedFailureModes": [],
  "sources": [
    {
      "title": "zkSecurity — ZK security audits and cryptographic engineering",
      "url": "https://zksecurity.xyz/",
      "kind": "provider"
    },
    {
      "title": "zkSecurity — public audit reports",
      "url": "https://zksecurity.xyz/reports/",
      "kind": "audit reports"
    },
    {
      "title": "Clean — Lean circuit DSL developed by zkSecurity",
      "url": "https://github.com/Verified-zkEVM/clean",
      "kind": "code and documentation"
    },
    {
      "title": "Introducing Clean, a formal verification DSL for ZK circuits in Lean 4 (zkSecurity)",
      "url": "https://blog.zksecurity.xyz/posts/clean/",
      "kind": "technical introduction"
    },
    {
      "title": "zk.golf — circuit optimisation challenges verified in Lean 4",
      "url": "https://zk.golf/",
      "kind": "learning and practice"
    },
    {
      "title": "Veridise — zero-knowledge audit services",
      "url": "https://veridise.com/audits/zk/",
      "kind": "provider"
    },
    {
      "title": "Veridise — security proofs for cryptographic protocols",
      "url": "https://veridise.com/security/security-proofs/",
      "kind": "provider"
    },
    {
      "title": "Zellic — ZK circuit and applied cryptography security assessments",
      "url": "https://www.zellic.io/",
      "kind": "provider"
    },
    {
      "title": "clean — Lean 4 DSL for writing and formally verifying ZK circuits",
      "url": "https://github.com/Verified-zkEVM/clean",
      "kind": "tool"
    }
  ],
  "updated": "2026-09-12",
  "version": "1.3",
  "canonical": "https://zkpick.com/audit/consultancies/",
  "authors": [
    "MarketComp"
  ]
}